Analytics BIOC
Low
✕
Uncommon creation or access operation of sensitive shadow copy
An uncommon creation or access of a sensitive Shadow Copy volume path.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: OS Credential Dumping (T1003)
Attacker's goals:
Attackers may try to copy sensitive data or dump OS credentials from the host file system by using Shadow Copy volume utilities.
Investigative actions:
Verify if the shadow copy operation is part of an IT activity. Look for other hosts performing the same shadow copy event with similar causality process behavior.* Inspect the causality process and its characteristics as they appear on other hosts.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- Uncommon creation or access operation of sensitive shadow copy by a remote actor Low
- Uncommon creation or access operation of sensitive shadow copy by a high-risk process High (parent: Low)